CVE-2026-77812: CWE-311 Missing Encryption of Sensitive Data in DJI Neo
Description
CVE-2026-77812 is a critical vulnerability affecting multiple DJI drone models where sensitive Wi-Fi credentials are transmitted over Bluetooth Low Energy (BLE) without encryption. An attacker within BLE range can passively capture these credentials, including the Wi-Fi SSID, PSK, and session UUID, enabling unauthorized access to the drone's Wi-Fi network and services. The credentials remain valid indefinitely unless manually reset, and the attack leaves no indication of compromise. A firmware update from DJI is required to remediate this issue.
CVSS v4.0
Score 9.4critical
Affected software
DJI
Neo
DJI
Neo 2
DJI
DJI Flip
DJI
Air 3
DJI
Air 3S
DJI
Avata 2
DJI
Avata 360
DJI
Mavic 3
DJI
Mavic 3 Classic
DJI
Mavic 3 Pro
DJI
Mavic 4 Pro
DJI
Mini 2
DJI
Mini 3
DJI
Mini 3 Pro
DJI
Mini 4 Pro
DJI
Mini 5 Pro
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DJI drones transmit DUML protocol messages over BLE unencrypted, including Wi-Fi credentials exchanged during connection attempts or QuickTransfer mode. An attacker with a BLE sniffer can passively capture the Wi-Fi SSID, PSK, and session UUID, which uniquely identifies trusted clients. This allows the attacker to join the drone's Wi-Fi network, interact with exposed services, and decrypt traffic. The credentials do not change between sessions unless manually reset, and the attack is fully passive, leaving no trace. Affected models include various DJI Neo, Flip, Air, Avata, Mavic, and Mini drones with firmware versions below specified thresholds. Remediation requires a vendor firmware update.
Potential Impact
An attacker within BLE range can recover Wi-Fi credentials in cleartext, join the drone's internal Wi-Fi network, bypass client authentication by replaying the session UUID, and decrypt Wi-Fi traffic between the drone and legitimate users. The vulnerability allows persistent unauthorized access without detection, posing significant confidentiality and integrity risks to drone communications and control.
Mitigation Recommendations
Remediation requires applying a firmware update from DJI. There is no effective user-side mitigation to fully address this vulnerability without upgrading the firmware. Users should monitor DJI advisories for the official patch release and update affected drones promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-21T14:06:52.579Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a885f67acd9273b493f93f5
Added to database: 08/21/2026, 14:23:35 UTC
Last enriched: 09/10/2026, 17:37:37 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 152
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.